3 ms·
Meanwhile, is there a way to restrict Dockerfiles, e.g. not allowing users to be root in the container? I had the impression that this technology was only usab
by LinuxFreedom 9y ago
Meanwhile, is there a way to restrict Dockerfiles, e.g. not allowing users to be root in the container?
I had the impression that this technology was only usable for the "single user machine" use-case, as too many bad things might happen in true multi-user environments - what is quite limiting in a unix world where we are used to multi-user reality since a long time - it was disturbing to see that such a successful tec seemed to ignore that.
However, I am really happy for any updates on this issue, I did not follow Docker development too much, so punish me when I am totally wrong!
- technofiend 9y agohttp://www.infoworld.com/article/3030558/application-virtualization/docker-goes-rootless-and-thats-a-good-thing.html http://www.infoworld.com/article/3030558/application-virtual... https://docs.docker.com/engine/installation/linux/linux-postinstall/#manage-docker-as-a-non-root-user https://docs.docker.com/engine/installation/linux/linux-post...
- raesene9 9y agoYep you can limit docker in a number of ways, to restrict what can be run in containers. Using user namespace support, root in a container is mapped to a non-root high UID user outside the container. You can also use cgroup support to limit the resources used by an individual container. There's quite a few recommendations in the Docker CIS security guide that can be helpful for locking down an installation https://benchmarks.cisecurity.org/tools2/docker/CIS_Docker_1.13.0_Benchmark_v1.0.0.pdf https://benchmarks.cisecurity.org/tools2/docker/CIS_Docker_1...